- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi everyone,
On my checkpoint 80.30 I would like to know, for a generic IPS log, which field tell me the direction of attack, in order to get who is the attacker, the pc or the server. I think that is simple for the checkpoint by looking the direction of the attack signature . Please do not confuse the session TCP/IP direcion with the attack direction.
thanks a lot.
Emi
Hello,
You could use the IPS Security Logs found in sk144192.
I hope this helps.
hi nick, thanks for answer, but I had already seen that sk, but there isn't a field for attack direction
I think that the attacks should be treated as correlated events and not by a single IPS log entry.
Whole point of multi-vector attacks is the difficulty in attribution and necessity of identifying all of their components.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY